Bonum Certa Men Certa

Perfectl is Not New, It's Not News About Linux, Outdated Apache RocketMQ is Not Linux, and the Real News Should be Back Doors Like Windows and CALEA Blunder

posted by Roy Schestowitz on Oct 16, 2024

Bruce Schneier

Perfectl Malware: At least he did not say Linux

"The malware has been circulating since at least 2021."

What malware?

"Perfectl Malware".

Linux?

No, not really. Really? Yes, really. Not Linux.

We've patiently tracked this FUD for a while now. It has been tracked in this page since the fifth of October (10+ days already and they're not done with their marketing campaign yet).

We were reluctant to write about it as it would give the FUD even more publicity, but now Schneier on Security mentions it, so it's getting more exposure anyway.

As an associate put it: "found on 'many' Linux machines? Really? Never heard of it prior to this..."

So for 3+ years it has been on "many" machines and somehow nobody mentioned it?

Weird.

As per my editorial comments (going over a week back), it seems like a marketing campaign, not research, and in order to properly rebut what this private company (Spamnil did a lot of spam for this company, so you know they're spammers) says we've been checking its claims. "My guess is that the article and others like it," an associate says, "are part of a larger orchestrated smear campaign to disparage FOSS heading into the upcoming decisions regarding computer and network security by US Congress and The White House."

"The articles contain a lot of lies and disinformation, in particular they wrongly assert that "any" Linux system is vulnerable. CUPS is Apple. Apache RocketMQ is not Linux either..."

Schneier says: "Something this complex and impressive implies that a government is behind this. North Korea is the government we know that hacks cryptocurrency in order to fund its operations. But this feels too complex for that. I have no idea how to attribute this."

Don't even go that far. Check what the basis is...

As noted above, it seems like a marketing/FUD campaign.

The AMX-30 is a main battle tank designed by Ateliers de construction d'Issy-les-Moulineaux and first delivered to the French Army in August 1965. The first five tanks were issued to the 501st Régiment de Chars de Combat in August of that year.

"The attribution is to point to the disinformation campaign coming via Redmond," our associate opines. "Maybe it is all a distraction from China (and reading between the lines, Russia) exploiting the CALEA backdoors with impunity for all these years. The same interests which back CALEA hate the idea of a move from Windows because they'd lose their back doors. That China, Russia, and every other country in the world are also in and out of Windows systems like a cheap motel does not matter to them. They only care that they themselves can also get in on demand. That's harder on GNU/Linux and Linux in general for many reasons including but not limited to the lack of a monoculture. tldr; The CALEA breaches have been pushed out of the news cycle prematurely."

A lot of the anti-"Linux" (even when it's not Linux; or even not the fault of Linux) FUD comes at strategic times for Microsoft and sometimes comes directly from Microsoft staff (Xz for instance). It's difficult to ignore the pattern.

"Another theme to be debunked," the associate adds, "amidst the stream of aspersions, insinuations, and disinformation, is the false premise that Microsoft is any kind of authority."

Microsoft is the culprit, not the expert, but it is expert at infiltrating positions of authority, especially in government [1, 2, 3, 4], in order to undermine real security and instead peddle snake-oil and lies.

The associate calls it after-market boondoggles "in place of secure design" and takes note of hours-old "victim blaming" by Microsoft, which "continues into a new decade..." (it says "Microsoft wants tougher punishments for cybercriminals"; how about the holes that facilitate these cybercriminals?)

He further notes that "targeting != breach, unless Windows(tm) is involved" (in which case, the holes are deliberate).

In short, there's some dodgy private company trying to promote itself by trash-talking "Linux" for over 10 days already (many shallow pieces in "the media"). But it's not about Linux, it's about servers that haven't been patched for ages and it's the fault of some outdated programs installed on them. The timing of this FUD (or marketing from this company's perspective) is hard to brush aside.

It's almost like this dodgy private company is attempting to sell something.

The FUD source

Other Recent Techrights' Posts

Hopefully Slopwatch is Dying
Some of the offending sites we used to keep abreast of descended into a lull
 
IBM's Mass Layoffs Will Continue Until Morale Improves
From recent hours
Links 07/12/2025: Political Catchup, Conflicts, Environmentalism
Links for the day
Gemini Links 07/12/2025: "Lazy Saturday" and Kubernetes With FreeBSD
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 06, 2025
IRC logs for Saturday, December 06, 2025
Links 06/12/2025: Science, Hardware, and Slop Fatigue
Links for the day
Contact Your National Representatives (Delegates) at the EPO, Here Are All the E-mail Addresses
We'll say more about this next week
Links 06/12/2025: Panic in the Slop (Chatbots) Industry and Perplexity Sued by New York Times for Plagiarising Articles Under Guise of "AI"
Links for the day
European Patent Office Issues: Points to Raise or Factoids to Share With Delegates of the EPO's Administrative Council
use their native language/tongue
European Readers, Get Ready to Contact Your National Representatives (Delegates) in the EPO's Administrative Council
Perfect timing might be Sunday or Monday
Why We'll Continue Our IBM/Red Hat Focus in 2026
There will be many more departures not only later this month but also next month
Links 06/12/2025: Slop's "Jeopardy Phenomenon" and RAM Shortage
Links for the day
Gemini Links 06/12/2025: Memories, "Sweetness and Burn", and Hope
Links for the day
Every Site That Uses Clownflare Had Worse Downtime/Uptime Record Than Ours
And the same goes for Azure and AWS
Software Freedom Conservancy (SFC) Does Not Work for Freedom, It Works to Secure the Massive Salary of Its President And Executive Director
We must be very effective then
Why (and When) I Become an 'Activist' Against Corruption and Abuse
The dictatorship bans criticism of the dictatorship. That's when there's a deadlock.
EPO Call for Action: Get Ready to Contact Your National Delegates, We Need to Remind Them That They Represent People
Today or tomorrow we'll publish contact details for national representatives in nearly 50 European nations
Links 05/12/2025: More Restrictions on Social Control Media and Slop, "Hype Can Turn to Backlash"
Links for the day
Like With Red Hat and Other IBM Acquisitions, the RAs (Layoffs) Seem to Already Extend to HashiCorp
Of course it is possible that HashiCorp staff just got PIP'ed or saw the writings on the wall and left [...] IBM is just a dying giant
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 05, 2025
IRC logs for Friday, December 05, 2025
Massachusetts Institute of Theft (MIT) Nowadays in the Business of Selling SPAM to Prop Up Fashionable Pyramid Schemes
There is nothing benign about it, more so when they misuse the MIT brand to lend credibility to elaborate schemes or scams
Many IBM Departures Today (Last Friday)
Way to go, IBM leadership
The Administrative Council of the European Patent Organisation Has More Reasons Than Cocainegate to Vote for Real Change in the European Patent Office
This is about democracy and accountability in Europe
Gemini Links 05/12/2025: Need for Simpler Systems, Molecular Dynamics, and More
Links for the day
Slopwatch: Not Much Today, Same as in Recent Weeks
Google News got 'conned' (maybe willingly) by one operator of several (at least 3) slopfarms that trash "Linux"
On IBM: "More Layoffs in Minnesota Are Coming" (Unverified Hearsay, for Now)
IBM is having loads of layoffs before the holidays
Links 05/12/2025: Openwashing by Microsoft's 'Open Source' Initiative, Unauthorised War Without Boundaries/Borders Waged by US
Links for the day
Finnish Politician Aura Salla Says Finland Must Dump Microsoft, Citing Security and Control Reasons, Not Costs
She says Finland should quit using Microsoft
Does This Pass the NDA "Sniff Test" at IBM?
In many companies, those who suck up to management get ahead
Links 05/12/2025: Slop Harming Democracy/Elections, More Bans Around the World on Kids' Use of Social Control Media
Links for the day
IBM Has No Layoffs, According to IBM, and According to the Media Parroting IBM
Another day of parrots (losers) who call themselves "journalists"
IBM Will Make You Unemployed On Christmas Eve
lists of people to cull
Within Weeks, Clownflare Has Collapsed Again, Time to Dump Clownflare
It's run by amateurs who, even if you maintain your site perfectly well, will render it inaccessible without prior notice
Cars Getting Worse and More Lethal
Who will be held accountable?
To "Take Back Control" Start With Actions Against 'Tech' (Mass Surveillance, Mass Censorship, Mass Control) Monopolies
collusion, price-fixing, a "cartel" of sorts
Beyond the Hype: Almost Nobody Uses Chatbots, Not Even 1% of Activity Online
3 years ago when Scam Altman (Microsoft) acted as if Google (search) was doomed a lot of the press got paid to pretend this was true
Rumour That Another IBM Round of Mass Layoffs (RAs) in Preparation Before the Current One is Even Completed
IBM still has strong brand recognition (because of its age and past might), but that won't last forever
Techrights Publication Pace to Increase Next Year
one is encouraged to stay indoors
Upgrading the Site
Debugging might be needed, so feedback helps
Why Microsoft is Panicking
Keep advocating (or "marketing") GNU/Linux to Vista 10 (or Vista 7) users... there are still over a billion of them "out there".
Web Developers in the US Can Already Disregard Mozilla, Firefox, and Firefox Users
"Last month, Firefox turned 21"
The Fate of "Blockchains" and "Metaverse" as a Sign of Things to Come for Slop ("AI")
Doesn't that tell us a lot about the modus operandi of these companies?
A Year After the Owner of X (Twitter) Performed Several Nazi Salutes on Stage the Germany-Based and Microsoft-Funded 'FSFE' Decides to Exit X (Twitter)
Will the real Free Software Foundation (FSF) follow suit?
EPO: What Comes Next
European media seems to have been sedated by soft bribes from cocaine addicts
Slopwatch: The Volume of Slop Has Certainly Gone Down a Lot Lately, Slop Image Providers Abandoned/Changed
It's a big improvement compared to past months
Thousands Laid Off at IBM, "Last Day" Yesterday
IBM is a dying company. This is a problem for Red Hat.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 04, 2025
IRC logs for Thursday, December 04, 2025
Gemini Links 05/12/2025: Espressif ESP32-C5 UEXT Module, Pixelfed, and the Web Getting Much Worse
Links for the day